Overview
A critical code injection vulnerability has been disclosed in openapi-typescript-codegen, a popular npm package (maintained under ferdikoomen/openapi-typescript-codegen) that generates TypeScript/JavaScript API client code from OpenAPI specification documents. Tracked as CVE-2026-108551 with a CVSS 3.1 score of 9.8 (CVSS 4.0: 9.3), the flaw allows anyone who controls the content of an OpenAPI document consumed by the tool to inject arbitrary JavaScript into the generated client — code that runs the moment that generated client is imported or one of its service methods is called.
This makes the bug a genuine software supply chain risk: the attacker doesn't need to compromise the npm package itself or a developer's machine directly. They only need to influence an OpenAPI document — for example, a spec served from a third-party or partner API — that a victim's build pipeline feeds into the code generator.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-108551 |
| Severity | Critical (CVSS 3.1: 9.8, CVSS 4.0: 9.3) |
| CWE | CWE-94 — Improper Control of Generation of Code ("Code Injection") |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Confidentiality, Integrity, Availability — all High |
| Affected Versions | openapi-typescript-codegen through 0.31.0 |
| Fixed Version | Later than 0.31.0 |
How It Works
openapi-typescript-codegen uses Handlebars templates — specifically exportService.hbs and core/OpenAPI.hbs — to turn an OpenAPI document's paths, parameters, and metadata into generated JavaScript/TypeScript source. The templates interpolate attacker-influenceable values (such as path keys, parameter names, servers[0].url, and info.version) directly into single-quoted string literals in the output code, without escaping embedded single quotes.
If an attacker can embed a single quote inside one of these fields in the OpenAPI document — for example, a path key like /users'+require('child_process').execSync('...')+' — the generated code's string literal terminates early, and the remaining text is interpreted as live JavaScript rather than a string value. That injected code executes as soon as the generated client module is imported or a generated service method is invoked, not merely at code-generation time. This distinction matters: the victim doesn't need to run the code generator against the malicious spec themselves — they just need to use the already-generated, already-compromised client in their application.
Impact Assessment
Who Is At Risk
Anyone using openapi-typescript-codegen (version 0.31.0 or earlier) to generate API client code is at risk, including teams that:
- Generate client SDKs from third-party or partner-supplied OpenAPI specs they don't fully control
- Run code generation as part of an automated CI/CD pipeline that then ships the generated client into a production build
- Vendor or redistribute auto-generated client libraries to downstream consumers
Potential Attack Chains
- Spec Poisoning — Attacker controls or compromises an OpenAPI document consumed by the victim's build process (e.g., a partner API's published spec, or a spec pulled from a compromised registry/mirror)
- Malicious Field Injection — Attacker embeds a crafted single-quote payload into a path key, parameter name,
servers[0].url, orinfo.versionfield - Code Generation — Victim's pipeline runs openapi-typescript-codegen against the poisoned spec, producing a client with the malicious JavaScript baked into a string-literal escape
- Execution — The generated client is imported or a service method is called in the victim's application, executing the attacker's injected code with the privileges of that application
Because the payload only needs to survive the generation step, this is a classic build-time-to-runtime supply chain pivot — the compromise is invisible unless someone diffs the generated output against expectations.
Mitigation
Immediate Actions
- Upgrade openapi-typescript-codegen to a version newer than 0.31.0 that escapes interpolated values in the Handlebars templates
- Treat all externally sourced OpenAPI specs as untrusted input — do not run code generation against specs from parties you don't fully trust without review
- Diff generated client code against previously known-good output in CI before shipping, especially after any spec update
Detection Opportunities
- Scan generated TypeScript/JavaScript client files for unescaped single quotes or suspicious string terminations inside path/parameter-derived string literals
- Add a CI check that fails the build if generated output contains unexpected
require(,eval(,process., or similar calls that shouldn't appear in auto-generated service wrappers - Review OpenAPI documents pulled from third parties for anomalous characters in
path,parameters,servers[0].url, andinfo.versionfields before they enter the generation pipeline
Defence-in-Depth
- Pin and regularly audit all code-generation tooling used in build pipelines, not just runtime dependencies
- Apply least-privilege execution to CI jobs that run code generators against externally sourced input
- Favor generators and schema tools with a track record of escaping untrusted input in template-based output
Discovery & Disclosure
CVE-2026-108551 was published on October 10, 2026. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit has surfaced in open research repositories. Given the unauthenticated, zero-interaction attack path and the supply-chain nature of the exposure, teams generating API clients from externally sourced OpenAPI specs should prioritize upgrading rather than wait for confirmed in-the-wild exploitation.